Hello,
I would like to connect two offices using a VPN tunnel, but Ive some difficulties.
Here the configurations:
Site1:
------
- ADSL with dynamic IP from the Provider, registered at DynDNS.org to have the host name available (site1.dyndns.org).
- The ADSL router (Motorola) as the LAN side configured to act as DHCP server on the range 192.168.20.0/24
- A ZyWall 2+ is connected to this router and get the IP address from it.
- In the DDNS settings on the ZyWall Ive the entry for site1.dyndns.org
- FW is enabled
- LAN is configured to be DHCP server to provide IP addresses to the PCs in the office (IP range 192.168.2.0/24)
VPN settings for Site1:
Gateway Policy Property Name: CompanyNetwork
Gateway Policy Setting
My ZyWALL: site1.dyndns.org
RemoteGateway Address: site2.dyndns.org
Network Policy Property
Active: YES
Name: Site1-To-Site2
Network Policy Setting
Local Network
Starting IP address: 192.168.2.1
Subnet Mask: 255.255.255.0
Remote Network: 192.168.1.1
Subnet Mask: 255.255.255.0
IKE Tullel Setting (IKE Phase 1)
Authentication for activating VPN
Authentication By
User Name
Password
Negotation Mode: Main Mode
Encryption Algorithm: 3DES
Authentication Algorithm : SHA1
Key Group : DH2
SA Life Time: 28800 s
Pre-Shared Key: MySharedKey1
IPSec Setting (IKE Phase 2)
Encapsulation Mode: Tunnel Mode
IPSec Protocol: ESP
Encryption Algorithm : DES
Authentication Algorithm : SHA1
SA Life Time: 28800 s
Perfect Forward Secrecy (PFS): None
Site2:
------
- ADSL with dynamic IP from the Provider, registered at DynDNS.org to have the host name available (site2.dyndns.org).
- The ADSL router (ZyXEL P600H-D3) as the LAN side configured to act as DHCP server on the range 192.168.10.0/24, FW disabled
- A ZyWall 2+ is connected to this router and get the IP address from it.
- In the DDNS settings on the ZyWall Ive the entry for site2.dyndns.org
- FW is enabled
- LAN is configured to be DHCP server to provide IP addresses to the PCs in the office (IP range 192.168.1.0/24)
VPN settings for Site2:
Gateway Policy Property Name: CompanyNetwork
Gateway Policy Setting
My ZyWALL: site2.dyndns.org
RemoteGateway Address: site1.dyndns.org
Network Policy Property
Active: YES
Name: Site2-To-Site1
Network Policy Setting
Local Network
Starting IP address: 192.168.1.1
Subnet Mask: 255.255.255.0
Remote Network: 192.168.2.1
Subnet Mask: 255.255.255.0
IKE Tullel Setting (IKE Phase 1)
Authentication for activating VPN
Authentication By
User Name
Password
Negotation Mode: Main Mode
Encryption Algorithm: 3DES
Authentication Algorithm : SHA1
Key Group : DH2
SA Life Time: 28800 s
Pre-Shared Key: MySharedKey1
IPSec Setting (IKE Phase 2)
Encapsulation Mode: Tunnel Mode
IPSec Protocol: ESP
Encryption Algorithm : DES
Authentication Algorithm : SHA1
SA Life Time: 28800 s
Perfect Forward Secrecy (PFS): None
-----
When I test the connection, VPN tunnel is not established.
In the LOG of both ZyWall's I see that the DNS resolution of the 2 sites are OK,
but I've the error: IKE Packet Retrasmit
I've try in different way to debug it but without success.
Do you have any idea what could be the problem?
How can I have a more detaield log for helping debugging?
Thank you for your help.
FP